Denial of Service Vulnerability in Wireshark's K12 RF5 File Parser
CVE-2026-5404

4.7MEDIUM

Key Information:

Vendor

Wireshark

Status
Vendor
CVE Published:
30 April 2026

What is CVE-2026-5404?

A vulnerability in Wireshark's K12 RF5 file parser can cause a crash, potentially leading to a denial of service when processing specially crafted files. This issue affects multiple versions of Wireshark, including those in the 4.6.x and 4.4.x series. Attackers may exploit this vulnerability to disrupt functionality, which can have significant implications for users relying on Wireshark for network analysis. It is imperative for users to update to the latest versions that address this issue.

Affected Version(s)

Wireshark 4.6.0 < 4.6.5

Wireshark 4.4.0 < 4.4.15

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

TODO
.